Courseiva

SAP-C02 Continuous Improvement for Existing Solutions Practice Question

A company operates a multi-account AWS Organization with AWS Control Tower. A new compliance rule requires that all Amazon S3 buckets in every account block public access and that any noncompliant bucket be remediated automatically within minutes. The security team wants a central view of compliance and minimal per-account configuration. Which solution BEST meets these requirements?

⚠ Common exam trap

The trap here is choosing a detection-only mechanism such as Control Tower guardrails or Security Hub, and overlooking that automatic remediation within minutes requires AWS Config remediation actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access at the organization level using AWS Organizations, and deploy an AWS Config conformance pack with automatic remediation in each account.

Organization-level S3 Block Public Access enforces the setting across all accounts and future accounts from a single place, satisfying the central control requirement. AWS Config conformance packs with automatic remediation detect noncompliant buckets and fix them quickly. Together they provide both preventive enforcement and automatic corrective action with little per-account effort.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable S3 Block Public Access at the organization level using AWS Organizations, and deploy an AWS Config conformance pack with automatic remediation in each account.

    Why this is correct

    Organization-level S3 Block Public Access applies the setting to every current and future account in the organization, so new accounts inherit it automatically. An AWS Config conformance pack with automatic remediation detects and fixes any bucket that is later made public. This combination gives central enforcement plus automatic remediation with minimal per-account setup.

  • ✗

    Create an IAM policy in the management account that denies s3:PutBucketPublicAccessBlock and attach it to every account's administrator role.

    Why it's wrong here

    An IAM policy that denies the API does not itself block public access on existing buckets, and attaching it to administrator roles across accounts requires per-account changes. It also does not remediate buckets that are already public or detect drift. The requirement for automatic remediation within minutes is not satisfied by a static deny policy.

  • ✗

    Use AWS Control Tower guardrails to detect public buckets and send findings to AWS Security Hub for manual review by the security team.

    Why it's wrong here

    Control Tower guardrails can detect noncompliance, but detection alone does not remediate buckets automatically within minutes. Routing findings to Security Hub still requires a human to act, which does not meet the automatic remediation requirement. It also does not apply the block public access setting to new accounts as directly as an organization-level policy.

  • ✗

    Deploy an AWS Lambda function in each account that runs on a schedule to call PutBucketPublicAccessBlock for every bucket.

    Why it's wrong here

    A scheduled Lambda function per account requires custom code, IAM roles, and deployment in every account, which contradicts the minimal per-account configuration goal. Scheduled execution may also take longer than minutes to detect and fix a newly public bucket. It lacks a central compliance view and is more operationally burdensome than managed AWS Config remediation.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SAP-C02 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.